Re: OpenBSD firewalls as virtual machine ?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: misc <misc@...>
Date: Saturday, September 22, 2007 - 12:36 am

On Fri, Sep 21, 2007 at 11:12:10PM -0400, user@domain.invalid.holland-consulting.net wrote:

Hi Nick.

I understand your reasons. To me they look like reasons for separate
firewalls on separate boxes. In the scenarios you mention, would you
put separate firewalls on one machine?

If I was going to put them all on one machine, I'd separate the
administration of the box itself (me) from the people responsible for
rule sub-sets. E.g. if one sub-firewall is dealing with traffic between
NICs 1 & 2 (call it channel A), another between NICs 3 & 4 (call it
channel B), I'd have the channels A and B admins submit rules sub-sets
via rsync to the box. My script would then sanity check (ensure that
they only dealt with the interfaces they were assigned) then incorporate
all of them into a master rule-set that would then get tested and then
put on-line. I would think that this, being only one firewall, would be
simpler than several firewalls in VMs on one box; possibly more secure
given the comments in this thread about the porus isolation between VMs.

That's just how I would think of it. OTOH, I've never done any
virtualization and never been into a proper data center.

Doug.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OpenBSD firewalls as virtual machine ?, Josh, (Thu Sep 20, 9:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Die Gestalt, (Mon Sep 24, 8:56 am)
Re: OpenBSD firewalls as virtual machine ?, David Gwynne, (Mon Sep 24, 7:59 am)
Re: OpenBSD firewalls as virtual machine ?, Eduardo Tongson, (Sat Sep 22, 11:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Bryan Irvine, (Fri Sep 21, 7:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Kent Watsen, (Fri Sep 21, 8:07 am)
Re: OpenBSD firewalls as virtual machine ?, Scott Wells, (Fri Sep 21, 9:19 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Fri Sep 21, 10:52 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Sat Sep 22, 12:36 am)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Sat Sep 22, 10:53 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Sat Sep 22, 11:36 am)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 11:17 am)
Re: OpenBSD firewalls as virtual machine ?, Henning Brauer, (Sat Sep 22, 7:29 am)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Fri Sep 21, 3:29 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 5:15 pm)
Re: OpenBSD firewalls as virtual machine ?, Stuart Henderson, (Fri Sep 21, 3:51 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 5:16 pm)
Re: OpenBSD firewalls as virtual machine ?, Claudio Jeker, (Fri Sep 21, 6:34 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 8:06 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Sat Sep 22, 7:35 pm)
Re: OpenBSD firewalls as virtual machine ?, n0g0013, (Sat Sep 22, 8:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 7:10 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Fri Sep 21, 10:48 am)
Re: OpenBSD firewalls as virtual machine ?, Ted Unangst, (Fri Sep 21, 4:28 pm)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 11:09 am)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 8:58 am)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Thu Sep 20, 9:52 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Sat Sep 22, 7:45 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Fri Sep 21, 2:18 am)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 4:03 am)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 9:35 pm)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Thu Sep 20, 9:53 pm)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 10:15 pm)